Free Exam Questions Practice & Download

Latest & Trending: Claude CCAR-F, DP-750, AZ-900, AI-901, AZ-104, AI-102, AI-103, AI-300, SAA-C03, AWS AIP-C01, Cybersecurity - CC
🌟 Latest Practice Q&A
🌟 Verified by Experts
🌟 Trusted by Professionals

Microsoft : AZ-305

⭐⭐⭐⭐⭐ 4587 Satisfied Users

Jul 27,2026
Last Updated

284 Total Question

Designing Microsoft Azure Infrastructure Solutions
Regular Updated Actual Material | Pass with confidence

  • 24/7 Customer Support
  • 90 Days Free Updates
  • 59,000+ Satisfied Customers
  • Instant Download under Premium
98% Pass Rate 👑 Upgrade to Premium
Trusted By Millions of Certified Professionals 🎓 — now it's YOUR turn!
Latest Exam Pattern • Real Exam Questions • Verified Answers Practice with actual exam-like questions and boost your confidence!
Upgrade to Premium
Unlock Full PDF Access
  • Actual Exam Q&A (284)
  • Instant Access to Full PDF Download
  • Printable format/Offline Study
  • Regularly Updated
  • 90 Days Free Updates
  • 24/7 Customer Support
  • Compatibility:

    🌐 🖥️ 📱 Compatible with all Devices
Bundle DISCOUNT OFFER
Extra 50% OFF (FULL PDF + TEST PRACTICE)
Get Full PDF + Test Practice
  • Save up to 50% with Bundle Package
  • 80% choose PDF+ Online Practice Togethor
  • Printable/PDF + Unlimited Mock Test to Ensure best practice
  • 90 Days Free Updates
  • 24/7 Customer Support
  • Compatibility:
    🌐 🖥️ 📱 All Browsers and Devices

About AZ-305 Exam


Prepare for Microsoft Exam AZ-305 and demonstrate your real-world mastery of designing Azure infrastructure solutions. This certification is ideal for cloud architects and senior IT professionals who translate business requirements into secure, scalable, and reliable Azure architectures.
Recommend you to use our Exam AZ-305 actual test practice material latest version to ensure best practices and first-attempt pass guaranteed!
— Exam Topics
Design identity, governance, and monitoring solutions (25–30%)
Design data storage solutions (20–25%) examsbrite.com +2
Design business continuity solutions (15–20%)
Design infrastructure solutions (30–35%)
Microsoft Azure Solutions Architect Expert AZ-305 Exam Format
— AZ-305 Exam Format:
Exam code – AZ-305
Exam type – Proctored
Exam duration – ~ 120 minutes (though some sources say up to 150 minutes including survey) Vision Training Systems +2 ExamCollection +2
Exam length – 40–60 questions
Passing score – 700 / 1000
Delivery languages – English, Japanese, Chinese (Simplified), Korean, German, French, Spanish, Portuguese (Brazil), Chinese (Traditional), Italian, Indonesian (Indonesia)
Additional study materials – Self-paced Microsoft Learn modules, case-study practice, architectural design labs. Microsoft provides a detailed study guide. +1
Exam Level – Expert / Architect
Role – Azure Solutions Architect
Renewal Frequency – Microsoft certifications typically need renewal; refer to Microsoft Learn for the current policy.

📘 Free AZ-305 Sample Questions

Question No. 1
AZ-305 Exam Question
You have an Azure subscription that contains a custom application named Application1. Application1 was developed by an external company named Fabrikam,
Ltd. Developers at Fabrikam were assigned role-based access control (RBAC) permissions to the Application1 components. All users are licensed for the
Microsoft 365 E5 plan.
You need to recommend a solution to verify whether the Fabrikam developers still require permissions to Application1. The solution must meet the following requirements:
✑ To the manager of the developers, send a monthly email message that lists the access permissions to
Application1.
✑ If the manager does not verify an access permission, automatically revoke that permission.
✑ Minimize development effort. What should you recommend?
A In Azure Active Directory (Azure AD), create an access review of Application1.
B Create an Azure Automation runbook that runs the Get-AzRoleAssignment cmdlet.
C In Azure Active Directory (Azure AD) Privileged Identity Management, create a custom role assignment for the Application1 resources.
D Create an Azure Automation runbook that runs the Get-AzureADUserAppRoleAssignment cmdlet.
Correct Answer: A. In Azure Active Directory (Azure AD), create an access review of Application1.
Explanation: In Azure Active Directory (Azure AD), create an access review of Application1.
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/governance/manage-user-access-with-access- reviews
Question No. 2
AZ-305 Exam Question
You have an Azure subscription. The subscription has a blob container that contains multiple blobs.
Ten users in the finance department of your company plan to access the blobs during the month of April. You need to recommend a solution to enable access to the blobs during the month of April only.
Which security solution should you include in the recommendation?
A shared access signatures (SAS)
B Conditional Access policies
C certificates
D access keys
Correct Answer: A. shared access signatures (SAS)
Explanation: Shared Access Signatures (SAS) allows for limited-time fine grained access control to resources. So you can generate URL, specify duration (for month of April) and disseminate URL to 10 team members. On May 1, the SAS token is automatically invalidated, denying team members continued access.

Reference:
https://docs.microsoft.com/en-us/azure/storage/common/storage-sas-overview
Question No. 3
AZ-305 Exam Question
You have an Azure Active Directory (Azure AD) tenant that syncs with an on-premises Active Directory domain. You have an internal web app named WebApp1 that is hosted on-premises. WebApp1 uses Integrated Windows authentication.
Some users work remotely and do NOT have VPN access to the on-premises network. You need to provide the remote users with single sign-on (SSO) access to WebApp1.
Which two features should you include in the solution? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
A Azure AD Application Proxy
B Azure AD Privileged Identity Management (PIM)
C Conditional Access policies
D Azure Arc
E Azure AD enterprise applications
F Azure Application Gateway
Correct Answer: A. Azure AD Application Proxy
Explanation: A: Application Proxy is a feature of Azure AD that enables users to access on-premises web applications from a remote client. Application Proxy includes both the
Application Proxy service which runs in the cloud, and the Application Proxy connector which runs on an on- premises server.
You can configure single sign-on to an Application Proxy application. E: Add an on-premises app to Azure AD
Now that you've prepared your environment and installed a connector, you're ready to add on-premises applications to Azure AD.
1. Sign in as an administrator in the Azure portal.
2. In the left navigation panel, select Azure Active Directory.
3. Select Enterprise applications, and then select New application.
4. Select Add an on-premises application button which appears about halfway down the page in the On- premises applications section. Alternatively, you can select Create your own application at the top of the page and then select Configure Application Proxy for secure remote access to an on-premise application.
5. In the Add your own on-premises application section, provide the following information about your application.
6. Etc. Incorrect:
Not C: Conditional Access policies are not required.

Reference:
https://docs.microsoft.com/en-us/azure/active-directory/app-proxy/application-proxy-add-on-premises-appli cation
Question No. 4
AZ-305 Exam Question
You have an Azure Active Directory (Azure AD) tenant named contoso.com that has a security group named Group1. Group1 is configured for assigned membership. Group1 has 50 members, including 20 guest users.
You need to recommend a solution for evaluating the membership of Group1. The solution must meet the following requirements:
✑ The evaluation must be repeated automatically every three months.
✑ Every member must be able to report whether they need to be in Group1.
✑ Users who report that they do not need to be in Group1 must be removed from Group1 automatically.
✑ Users who do not report whether they need to be in Group1 must be removed from Group1 automatically. What should you include in the recommendation?
A Implement Azure AD Identity Protection.
B Change the Membership type of Group1 to Dynamic User.
C Create an access review.
D Implement Azure AD Privileged Identity Management (PIM).
Correct Answer: C. Create an access review.
Explanation: Azure Active Directory (Azure AD) access reviews enable organizations to efficiently manage group memberships, access to enterprise applications, and role assignments. User's access can be reviewed on a regular basis to make sure only the right people have continued access.
Reference:

https://docs.microsoft.com/en-us/azure/active-directory/governance/access-reviews-overview
Question No. 5
AZ-305 Exam Question
HOTSPOT -
You plan to deploy Azure Databricks to support a machine learning application. Data engineers will mount an Azure Data Lake Storage account to the Databricks file system. Permissions to folders are granted directly to the data engineers.
You need to recommend a design for the planned Databrick deployment. The solution must meet the following requirements:
✑ Ensure that the data engineers can only access folders to which they have permissions.
✑ Minimize development effort.
✑ Minimize costs.
What should you include in the recommendation? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
Hot Area:
A
Correct Answer: A.
Explanation: Box 1: Premium -
Premium Databricks SKU is required for credential passhtrough.

Box 2: Credential passthrough -
Athenticate automatically to Azure Data Lake Storage Gen1 (ADLS Gen1) and Azure Data Lake Storage Gen2 (ADLS Gen2) from Azure Databricks clusters using the same Azure Active Directory (Azure AD) identity that you use to log into Azure Databricks. When you enable Azure Data Lake Storage credential passthrough for your cluster, commands that you run on that cluster can read and write data in Azure Data Lake Storage without requiring you to configure service principal credentials for access to storage.

Reference:
https://docs.microsoft.com/en-us/azure/databricks/security/credential-passthrough/adls-passthrough
Question No. 6
AZ-305 Exam Question
HOTSPOT -
You plan to deploy an Azure web app named App1 that will use Azure Active Directory (Azure AD) authentication. App1 will be accessed from the internet by the users at your company. All the users have computers that run Windows 10 and are joined to Azure AD.
You need to recommend a solution to ensure that the users can connect to App1 without being prompted for authentication and can access App1 only from company-owned computers.
What should you recommend for each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
Hot Area:
A
Correct Answer: A.
Explanation: Box 1: An Azure AD app registration
Azure active directory (AD) provides cloud based directory and identity management services.You can use azure AD to manage users of your application and authenticate access to your applications using azure active directory.
You register your application with Azure active directory tenant. Box 2: A conditional access policy
Conditional Access policies at their simplest are if-then statements, if a user wants to access a resource, then they must complete an action.
By using Conditional Access policies, you can apply the right access controls when needed to keep your organization secure and stay out of your user's way when not needed.

Reference:
https://codingcanvas.com/using-azure-active-directory-authentication-in-your-web-application/ https://docs. microsoft.com/en-us/azure/active-directory/conditional-access/overview
Question No. 7
AZ-305 Exam Question
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your company deploys several virtual machines on-premises and to Azure. ExpressRoute is deployed and configured for on-premises to Azure connectivity.
Several virtual machines exhibit network connectivity issues.
You need to analyze the network traffic to identify whether packets are being allowed or denied to the virtual machines.
Solution: Use Azure Traffic Analytics in Azure Network Watcher to analyze the network traffic. Does this meet the goal?
A Yes
B No
Correct Answer: B. No
Explanation: (Traffic Analytics) under (Network Watcher) gives you statistical data and traffic visualization like total inbound and outbound flows and the number of deployed NSGs. However, it doesn't give you information if packets are allows of denied. Check screenshot in the following reference: https://docs.microsoft.com/en- us/azure/network-watcher/traffic-analytics
(IP Flow Verify) under (Network Watcher) gives you option to verify if traffic is allowed or denied. Check screenshot in the following reference: https://docs.microsoft.com/en-us/azure/network-watcher/network- watcher-ip-flow-verify-overview
Correct answer is B.
Question No. 8
AZ-305 Exam Question
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your company deploys several virtual machines on-premises and to Azure. ExpressRoute is deployed and configured for on-premises to Azure connectivity.
Several virtual machines exhibit network connectivity issues.
You need to analyze the network traffic to identify whether packets are being allowed or denied to the virtual machines.
Solution: Use Azure Advisor to analyze the network traffic. Does this meet the goal?
A Yes
B No
Correct Answer: B. No
Explanation: Instead use Azure Network Watcher IP Flow Verify, which allows you to detect traffic filtering issues at a VM level.
Note: IP flow verify checks if a packet is allowed or denied to or from a virtual machine. The information consists of direction, protocol, local IP, remote IP, local port, and remote port. If the packet is denied by a security group, the name of the rule that denied the packet is returned. While any source or destination IP can be chosen, IP flow verify helps administrators quickly diagnose connectivity issues from or to the internet and from or to the on-premises environment.

Reference:
https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-ip-flow-verify-overview
Question No. 9
AZ-305 Exam Question
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
Your company deploys several virtual machines on-premises and to Azure. ExpressRoute is deployed and configured for on-premises to Azure connectivity.
Several virtual machines exhibit network connectivity issues.
You need to analyze the network traffic to identify whether packets are being allowed or denied to the virtual machines.
Solution: Use Azure Network Watcher to run IP flow verify to analyze the network traffic. Does this meet the goal?
A Yes
B No
Correct Answer: A. Yes
Explanation: Azure Network Watcher IP Flow Verify allows you to detect traffic filtering issues at a VM level.
IP flow verify checks if a packet is allowed or denied to or from a virtual machine. The information consists of direction, protocol, local IP, remote IP, local port, and remote port. If the packet is denied by a security group, the name of the rule that denied the packet is returned. While any source or destination IP can be chosen,
IP flow verify helps administrators quickly diagnose connectivity issues from or to the internet and from or to the on-premises environment.

Reference:
https://docs.microsoft.com/en-us/azure/network-watcher/network-watcher-ip-flow-verify-overview
Question No. 10
AZ-305 Exam Question
DRAG DROP -
You have an Azure subscription. The subscription contains Azure virtual machines that run Windows Server 2016 and Linux.
You need to use Azure Monitor to design an alerting strategy for security-related events.
Which Azure Monitor Logs tables should you query? To answer, drag the appropriate tables to the correct log types. Each table may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point. Select and Place:
A
Correct Answer: A.
Explanation: Windows : Event. Linux : Syslog
Reference:
https://docs.microsoft.com/en-us/azure/azure-monitor/platform/data-sources-windows-events https://docs.microsoft.com/en-us/azure/azure-monitor/agents/data-sources-syslog
Questions: 1-10 out of 284 Continue Full Practice.. GET ALL 284 QUESTIONS
AZ-305 Exam FAQ

Q1: What is AZ-305 exam questions, duration and passing score?

Level: Expert | Duration: 120 minutes | Questions: 40-60 | Passing Score: 700/1000
Role: Solutions Architect
Key Topics: Identity, data storage, business continuity, infrastructure design

Q2: What is the format of the AZ-305 certification exam?

The AZ-305 certification exam is 120 minutes long, containing 40 to 60 questions with a passing score of 700 out of 1000. It focuses on designing Azure infrastructure solutions covering identity, networking, storage, business continuity, and migration. Expect complex case studies and scenario-based questions that require architectural-level decision making throughout the exam.

Q3: How difficult is the AZ-305 exam and who should take it?

The AZ-305 is an expert-level certification exam requiring deep Azure knowledge and real-world architecture experience. It is best suited for candidates who have already passed AZ-104 and have hands-on infrastructure design experience. Exam preparation at this level demands thorough understanding of trade-offs between Azure services rather than simple feature memorization.

Q4: What is the recommended exam preparation approach for AZ-305?

AZ-305 exam preparation should involve studying Azure Well-Architected Framework pillars, reviewing architecture patterns from the Azure Architecture Center, and practicing complex case studies. Focus on identity governance, disaster recovery, hybrid connectivity, and cost optimization. Practice questions that challenge you to select the best design among multiple valid options are especially valuable for this exam.

Q5: Why should AZ-305 candidates practice with exam-style questions?

AZ-305 practice questions train you to think like an Azure architect by presenting real-world infrastructure challenges. Unlike knowledge recall, design exams test judgment and reasoning. Regularly working through practice questions with detailed explanations sharpens decision-making on topics like resiliency patterns, governance, and hybrid architecture, which are core focus areas of this certification exam.

Q6: What study resources are recommended for the AZ-305 exam?

Key study resources for AZ-305 include the Microsoft Azure Architecture Center, the Well-Architected Framework documentation, and AZ-104 prerequisite knowledge. Supplement these with case-study-focused practice questions and video courses from certified architects. ClearCatNet offers updated AZ-305 practice questions with explanations that help reinforce architectural thinking needed for this expert-level certification exam.

➡️ Under Premium Access, You will get:

3 Month FREE Access to our full Q&A PDF, Online Practice or both
Ensure success on your first attempt - Our top priority.
24/7 Service assurance at your satisfaction level

CLEARCATNET trusted by millions of Certified users with 98%  Pass RateBE NEXT YOU and GET CERTIFIED WITH EASE.

Popular Search:
AWS AIF-C01 exam questions answers , AWS CLF-C02 exam questions answers , AZ-900 Exam Questions Free , CIS-DF Exam Questions Free AWS SAA-C03 exam questions AZ-104 exam questions DP-900 exam questions

ClearCatNet provides original practice questions developed by certified professionals, aligned to official exam objectives. Our materials are designed to build genuine knowledge and test readiness — not to reproduce proprietary exam content."